diff options
Diffstat (limited to 'test/results/flow-info/default/heuristic_tcp_ack_payload.pcap.out')
-rw-r--r-- | test/results/flow-info/default/heuristic_tcp_ack_payload.pcap.out | 32 |
1 files changed, 16 insertions, 16 deletions
diff --git a/test/results/flow-info/default/heuristic_tcp_ack_payload.pcap.out b/test/results/flow-info/default/heuristic_tcp_ack_payload.pcap.out index 1a95b0232..ad0e39c70 100644 --- a/test/results/flow-info/default/heuristic_tcp_ack_payload.pcap.out +++ b/test/results/flow-info/default/heuristic_tcp_ack_payload.pcap.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] - analyse: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] + new: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] + analyse: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 28.648| 1.860| 7.030| 49424738.812| 1.100] [PKTLEN......: 42.000| 2960.000| 308.700| 576.000| 331721.900| 3.600] @@ -14,11 +14,11 @@ [ENTROPIES...: 4.7,4.8,4.7,5.8,4.4,5.8,7.2,7.3,4.7,7.4,4.8,4.7,6.2,6.3,7.6,7.6,6.6,5.4,6.1,4.4,4.7,5.4,7.5,5.4,4.7,4.5,6.0,5.6,7.8,4.4,4.5,5.5] DAEMON-EVENT: [Processed: 63 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [194.226.199.226][34101] -> [..8.247.226.126][...80] + new: [.....2] [ip4][..tcp] [194.226.199.226][34101] -> [..8.247.226.126][...80] guessed: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] [TLS][AmazonAWS][Web][Safe] - end: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] - new: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] - analyse: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] + end: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] + new: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] + analyse: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.030| 0.007| 0.011| 122.098| 3.500] [PKTLEN......: 42.000| 2864.000| 672.800| 1000.300| 1000640.100| 3.700] @@ -29,14 +29,14 @@ [PKTLENS.....: 52,52,42,258,46,2088,2088,462,42,42,133,318,109,42,217,361,78,46,78,364,1452,42,1452,2864,42,42,2864,42,2864,42,2864,42] [ENTROPIES...: 4.6,5.0,4.7,5.7,4.5,7.4,7.6,7.4,4.7,4.7,5.8,7.0,5.8,4.7,6.9,7.4,5.3,4.5,5.2,7.3,7.9,4.6,7.9,7.9,4.7,4.8,7.9,4.8,7.9,4.8,7.9,4.6] guessed: [.....2] [ip4][..tcp] [194.226.199.226][34101] -> [..8.247.226.126][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....2] [ip4][..tcp] [194.226.199.226][34101] -> [..8.247.226.126][...80] + end: [.....2] [ip4][..tcp] [194.226.199.226][34101] -> [..8.247.226.126][...80] DAEMON-EVENT: [Processed: 160 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 2|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..tcp] [..194.226.199.9][49756] -> [..92.223.106.21][..443] - new: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] + new: [.....4] [ip4][..tcp] [..194.226.199.9][49756] -> [..92.223.106.21][..443] + new: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] guessed: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] [TLS][GoogleCloud][Web][Safe] - end: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] - analyse: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] + end: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] + analyse: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 5.456| 0.293| 1.017| 1033283.961| 1.700] [PKTLEN......: 42.000| 2883.000| 385.900| 734.400| 539373.900| 3.400] @@ -46,8 +46,8 @@ [IATS(ms)....: 0.0,10.5,0.0,1548.8,0.0,1559.9,0.0,2.5,0.0,14.1,0.0,4.4,0.0,0.1,0.0,17.1,0.0,0.0,0.0,4.7,0.0,18.5,0.0,216.2,0.0,213.8,0.0,10.4,0.0,5455.6,0.0] [PKTLENS.....: 52,52,46,46,46,46,42,42,609,609,46,46,1450,1450,2883,2883,42,42,42,42,166,166,298,298,42,42,298,298,42,42,71,71] [ENTROPIES...: 4.5,4.5,4.8,4.8,4.8,4.8,4.8,4.8,7.1,7.1,4.6,4.6,7.2,7.2,7.5,7.5,4.7,4.7,4.7,4.7,6.3,6.3,7.1,7.1,4.8,4.8,7.1,7.1,4.7,4.7,5.2,5.2] - new: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] - analyse: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] + new: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] + analyse: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 2.635| 0.323| 0.688| 472790.598| 2.800] [PKTLEN......: 42.000| 2960.000| 481.700| 697.200| 486142.700| 3.800] @@ -58,9 +58,9 @@ [PKTLENS.....: 52,52,52,52,42,561,52,52,46,2960,1216,1500,52,46,1500,1500,1500,52,52,42,42,120,138,46,311,327,46,101,71,1500,658,673] [ENTROPIES...: 4.8,5.0,5.0,4.8,4.6,6.8,5.0,5.0,4.6,7.9,7.8,7.9,4.8,5.1,7.9,7.9,7.9,4.9,4.8,4.7,4.8,6.3,6.6,4.6,7.3,7.3,4.6,6.2,5.8,7.9,7.6,7.7] guessed: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] [TLS][Unknown][Web][Safe] - idle: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] + idle: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] guessed: [.....4] [ip4][..tcp] [..194.226.199.9][49756] -> [..92.223.106.21][..443] [TLS][Unknown][Web][Safe] - end: [.....4] [ip4][..tcp] [..194.226.199.9][49756] -> [..92.223.106.21][..443] + end: [.....4] [ip4][..tcp] [..194.226.199.9][49756] -> [..92.223.106.21][..443] guessed: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] [TLS][Unknown][Web][Safe] - end: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] + end: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] DAEMON-EVENT: shutdown |